Back to Malware Drops
be0abc2136f0ffa65cf9ae0cb9293133170ac990ae44d3f701671a796fa9abb4
MD55e60c5e1f91deb0f701c9e8d51eae5d6
SSDEEP—
File Typetext/x-script
Size2.0 KB
Sources2
Downloads0
First SeenJul 5, 2019
Last SeenJul 5, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Jul 5, 2019, 3:28:09 AMView attack session
- Dropped in this session (no command captured).Jul 5, 2019, 3:28:09 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 54[.]39[.]167[.]102
url (13)
- hxxp://54[.]39[.]167[.]102/apache2;
- hxxp://54[.]39[.]167[.]102/bash;
- hxxp://54[.]39[.]167[.]102/cron;
- hxxp://54[.]39[.]167[.]102/ftp;
- hxxp://54[.]39[.]167[.]102/ntpd;
- hxxp://54[.]39[.]167[.]102/nut;
- hxxp://54[.]39[.]167[.]102/openssh;
- hxxp://54[.]39[.]167[.]102/pftp;
- hxxp://54[.]39[.]167[.]102/sh;
- hxxp://54[.]39[.]167[.]102/sshd;
- hxxp://54[.]39[.]167[.]102/telnetd;
- hxxp://54[.]39[.]167[.]102/tftp;
- hxxp://54[.]39[.]167[.]102/wget;